logo

The Dark Knight Returns: Joker malware analysis

ID: 8c4bc4f7-8c66-5aa4-a35b-e60ec2c418de

STIX ID: report--8c4bc4f7-8c66-5aa4-a35b-e60ec2c418de

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2024-10-01

Date Updated: 2026-04-19

Author: Kacper Ratajczak

...
...

CERT Polska analysed a Joker-family Android application available on Google Play (com.onmybeauty.beautycamera) that uses obfuscated code and a native-assisted decryption routine to obtain and load a DEX payload. The malware communicates with C2 (kamisatu.top), downloads an encrypted payload (Kuwan), intercepts SMS, binds to mobile networks, automates WebView interactions to perform premium subscription transactions on behalf of users (including extracting SMS PINs), and thus enables fraudulent premium subscriptions; the report includes MD5 hashes and URLs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.